Live data from Hacker News

Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

theregister.com

41–50 of 73 posts

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#41
post #33

This claim that eIDAS is an attempt to intercept TLS and spy on citizens has been repeated over and over this week without any basis and I'm getting sick of it. I don't understand why everyone immediately assumes bad faith here when it's much more likely that this is just a botched article written by someone who has not had to deal with the intricacies of the web PKI. Do you seriously think the intent here is to allo…

> Do you seriously think the intent here is to allow, say, Italy to issue a certificate and spying on German citizens? This legislation allows and enables it, regardless of intent.

But that does not mean "Europe ready to intercept, spy..." or "EU Tries To Slip In New Powers To Intercept Encrypted Web..." as these articles are claiming.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#42
post #33

This claim that eIDAS is an attempt to intercept TLS and spy on citizens has been repeated over and over this week without any basis and I'm getting sick of it. I don't understand why everyone immediately assumes bad faith here when it's much more likely that this is just a botched article written by someone who has not had to deal with the intricacies of the web PKI. Do you seriously think the intent here is to allo…

Intent is important if you are attacking the character of the legislator. If we are criticizing the legislation itself then it's the effect of it we should be focusing on.

As in "what's the worst outcome that can come from this piece of legislation, assuming malicious intent from the person wielding this law in the future". If the answer to that is "uh, not good" then the legislation is bad.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#43
post #15

From the perspective of European govs: Why should only US entities (and companies like Cloudflare, Amazon or Google) be allowed to get access to communications content ? It’s very logical that Europe wants to do the same.

European CAs can apply to be included in the root stores, and Europeans can definitely write content-delivery (CDN) and content-parsing (browser) software.

European CAs were in root stores. The case in hand I wrote several times about is the Belgian Root CA that was in all major browsers until it was withdrawn somewhere in 2015..2017 in favor of Digicert for everything public services in Belgium.

This essentially gives a a free hand to NSA to spy non only on Belgians but also EU Institutions, NATO HQ, SWIFT and many more essential but not very public organizations headquartered in Belgium (ever heard of IPC? ENTSO-E?)

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#44
post #33

This claim that eIDAS is an attempt to intercept TLS and spy on citizens has been repeated over and over this week without any basis and I'm getting sick of it. I don't understand why everyone immediately assumes bad faith here when it's much more likely that this is just a botched article written by someone who has not had to deal with the intricacies of the web PKI. Do you seriously think the intent here is to allo…

It's also very much not the case; regulators adjusted that part of eIDAS earlier this week - Browsers aren't required to trust these certificates for DNS or HTTPS connections. The law is still in proposal/feedback stage and the lawmakers listened to the complaints.

TLS interception likely was never a seriously intended goal, just a side-effect due to how the law was worded.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#45
The problem the EU faces - or the respective national European intelligence agencies for that matter - is that they lack access to a comprehensive, global data funnel. The US, Russia and China all have their respective systems: The US has access to the data of Facebook (WhatsApp and Instagram), Apple messenger, Google's GMail. Russia has Telegram and China has I think Weibo, WeChat, TikTok and probably some more. I want to put the value of these data sources into question - as anti governmental actors increasingly learn to use other means for coordination - but still it's an attempt to get a foot into this global arms race.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#47
post #41

Earlier quoted context omitted.

> Do you seriously think the intent here is to allow, say, Italy to issue a certificate and spying on German citizens? This legislation allows and enables it, regardless of intent.

But that does not mean "Europe ready to intercept, spy..." or "EU Tries To Slip In New Powers To Intercept Encrypted Web..." as these articles are claiming.

> Europe ready to intercept, spy

That is what this legislation would enable, so this is accurate.

> EU Tries To Slip In New Powers To Intercept Encrypted Web

Again, that is what this legislation would enable, so this is also accurate.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#48
post #17
post #4

This is insane, and we should hurry up and prepare the technical ways to ensure we know it if we are served a different cert than everybody else. There's ongoing work on this field, but it is now a priority to have it ready.

It exists and works already: Certificate Transparency logs, HSTS and Cert Pinning are “protecting”. The first may have the side-effect (or intended ?) to inform US companies which websites you are visiting upon addition of new entries though…

> Certificate Transparency logs

CT logs are just, well, logs. They don't do anything to protect you from having your traffic intercepted via maliciously issued certificate. You might learn later (if somebody bothers to check) that it occurred but at that point the damage is already done.

> HSTS

This just says the connection should only be established via HTTPS, nothing more.

> Cert Pinning

Cert pinning has been removed both from Chromium and Firefox.

https://chromestatus.com/feature/5903385005916160

https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Rel...

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#49
post #23

We really need to go back to days of police actually going through the trouble of investigating and catching criminals - at least in principle. Now every government security agency dreams of having complete access to the communications of everyone so they don't go through the trouble of doing their job. First UK, now EU. Although I'm generally closer to the EU mentality of trusting the governments more than the corpo…

[flagged]

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#50

Useful other side discussion here: https://news.ycombinator.com/item?id=38187479 Important to note is that the main thing everyone is up in arms about, the TLS/HTTPS certificate stuff, already got adjusted after browser makers complained about it; browser makers aren't mandated to trust any certificates for internet traffic and DNS resolution. The only real problem left is QWACs in general being a part of the propose…

> The only real problem left is QWACs in general being a part of the proposed legislation from what I can tell.

See:

https://news.ycombinator.com/item?id=38189800

Post reply on HN